Back to Database
Status published
High
CVE-2020-28641
In Malwarebytes Free 4.1.0.56, a symbolic link may be used...
Vulnerability Description
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-28641
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.malwarebytes.com
- https://support.malwarebytes.com/hc/en-us/articles/360058885974-Arbitrary-file-deletion-vulnerability-fixed-in-Malwarebytes-for-Windows
- https://support.malwarebytes.com/hc/en-us/articles/1500000403501-Arbitrary-file-deletion-vulnerability-fixed-in-Malwarebytes-Endpoint-Protection
More from malwarebytes
View All →CVE-2022-25150
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed...
High
7.8
CVE-2020-25533
An issue was discovered in Malwarebytes before 4.0 on macOS....
High
7
CVE-2020-11507
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could...
High
7.8
CVE-2019-19929
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1...
High
7.8
CVE-2018-5279
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local...
Unknown
0
Affected Vendor
malwarebytes
View all reports →Affected Software
endpoint protection, malwarebytes
Vulnerable Versions:
0, 4.1.0.56
Timeline
Official Publish:
December 22nd, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.